Product:

Whatsapp

(Whatsapp)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 39
Date Id Summary Products Score Patch Annotated
2017-05-18 CVE-2017-8769 Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat deletion, or who expect encryption (consistent with the application's use of an encrypted database to store chat text). NOTE: the vendor reportedly indicates that they do not "consider these to be security issues" because... Whatsapp 4.6
2019-07-16 CVE-2019-3571 An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. Whatsapp 5.3
2023-10-04 CVE-2023-38537 A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability. Whatsapp 5.6
2023-10-04 CVE-2023-38538 A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability. Whatsapp 5.0
2019-10-03 CVE-2019-11932 A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image. Android\-Gif\-Drawable, Whatsapp 8.8
2020-01-21 CVE-2019-18426 A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message. Whatsapp, Whatsapp_for_desktop 8.2
2022-09-22 CVE-2022-36934 An integer overflow in WhatsApp could result in remote code execution in an established video call. Whatsapp 9.8
2022-09-23 CVE-2022-27492 An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file. Whatsapp 7.8
2021-04-06 CVE-2021-24027 A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material. Whatsapp, Whatsapp_business 7.5
2022-03-23 CVE-2020-20096 Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. Whatsapp 6.5